tw-digitals[.]com
PhishDestroy identifies tw-digitals.com as an active generic phishing domain masquerading as a legitimate digital services provider. The site is currently distributing a drainer kit designed to harvest cryptocurrency wallet credentials and sensitive financial data from unsuspecting victims. No specific brand impersonation has been confirmed at this stage, but the threat actor behind this campaign employs deceptive landing pages mimicking popular digital service interfaces to lure targets into entering their credentials or downloading malicious payloads.
This domain was flagged through PhishDestroy’s continuous monitoring pipeline. Technical indicators confirm the following: the domain tw-digitals.com resolves to IP 188.114.97.3 and was registered on April 12, 2026, through Global Domain Group LLC. The site holds a valid SSL certificate issued by Let’s Encrypt and currently shows 4/95 detections on VirusTotal, indicating it remains under the radar of most detection engines. As of this report, the domain is not listed in Google Safe Browsing (GSB) and has not been added to major blocklists, leaving users vulnerable to exposure. The newly registered status and clean VT score suggest an ongoing, low-profile campaign with potential for rapid expansion.
As of this writing, the campaign is considered active with undetermined scale. PhishDestroy has flagged the domain and is sharing indicators with threat intelligence partners. While no mass-blocking is yet enforced, users are strongly advised to block access to tw-digitals.com at the network level and avoid visiting the site. Remaining risk is assessed as moderate-to-high due to the domain’s recent deployment, lack of detection coverage, and the potential for rapid replication across related domains or infrastructure. Organizations are urged to update firewall rules, email security policies, and endpoint protection systems to block traffic to 188.114.97.3 and monitor for any emerging variants derived from the same seed (e726d1).
Запис надісланого повідомлення
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260426-74A916- Заголовок збереженої сторінки
- Loading…
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | tw-digitals.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 09.08.2026
Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
Збережене спостереження
Збережене спостереження: alive → dead
-
Збережене спостереження
Збережене спостереження: dead → alive
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено технологій із високою впевненістю: 10
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of tw-digitals.com · checked Apr 26, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога